Published on: 10 June 2026
Ivanti has released security advisories to address the vulnerabilities in Ivanti products. Detailed information about the vulnerabilities can be found at:
https://forums.ivanti.com/s/article/kA1UL00000091Xx0AI
https://forums.ivanti.com/s/article/kA1UL000000905d0AA
https://forums.ivanti.com/s/article/kA1UL000000907F0AQ
Reports indicated that a remote code execution vulnerability (CVE-2026-6973) is being exploited in the wild. Additionally, proof-of-concept (PoC) exploit code is available for denial of service vulnerability (CVE-2026-49975, known as HTTP/2 Bomb). System administrators are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
For detailed information of the affected systems, please refer to the corresponding security advisories at vendor's website.
Successful exploitation of the vulnerabilities could lead to remote code execution or security restriction bypass on an affected system.
Patches for affected systems are available. System administrators of affected systems should follow the recommendations provided by the vendor and take immediate actions to mitigate the risk.